Posts by beyondmachines1@infosec.exchange
 (DIR) Post #B4qPKRIPmgkD7wIJHc by beyondmachines1@infosec.exchange
       0 likes, 1 repeats
       
       Next time you read a finance/tech bro or a corporate drone complain about employees not being loyal and committed, remember this:
       
 (DIR) Post #B4sc2xrndU64eQlMES by beyondmachines1@infosec.exchange
       0 likes, 1 repeats
       
       AI Tool Discovers Critical Zero-Day Vulnerabilities in ImageMagick Default PoliciesOctagon Networks report vulnerabilities in ImageMagick's default and secure policies, allowing remote code execution and arbitrary file access across millions of Linux and WordPress servers. The flaws exploit format detection logic and unblocked delegates to bypass standard security hardening.**If you are using ImagMagicks, first set the policy to limited. Disable GhostScript if your server does not strictly require PDF or PostScript processing to eliminate the primary execution engine for these attacks. Always use a strict allow-list policy for ImageMagick coders rather than relying on the default settings provided by your operating system.**#cybersecurity #infosec #advisory #vulnerabilityhttps://beyondmachines.net/event_details/ai-tool-discovers-critical-zero-day-vulnerabilities-in-imagemagick-default-policies-e-j-h-0-a/gD2P6Ple2L
       
 (DIR) Post #B4uqD8e8CSGwea2E0O by beyondmachines1@infosec.exchange
       0 likes, 1 repeats
       
       LinkedIn Is Quietly Scanning Your Browser Every Time You VisitResearch published on browsergate.eu reports that LinkedIn silently scans visitors' Chromium-based browsers for over 6,000 installed extensions, revealing indicators of sensitive personal data like religion, health, politics, and job-search activity. The platform can easily link findings to identified user profiles, which raises serious GDPR, ePrivacy, and general privacy and legal concerns.**Switch to Firefox for LinkedIn, or use a separate Chrome profile with no extensions installed when visiting the site. And load up on all ad and script blocker extensions you can find, like Ublock Origin, Ublock Lite, Privacy Badger...**#cybersecurity #infosec #knowledge #awarenesshttps://beyondmachines.net/event_details/linkedin-is-quietly-scanning-your-browser-every-time-you-visit-m-0-k-n-h/gD2P6Ple2L
       
 (DIR) Post #B53poCoPK6pUkxalMW by beyondmachines1@infosec.exchange
       1 likes, 0 repeats
       
       But, why?
       
 (DIR) Post #B5CFoTEWQColl6Gzke by beyondmachines1@infosec.exchange
       1 likes, 4 repeats
       
       Lo and behold
       
 (DIR) Post #B5W1ioCK3BW2qQqgxE by beyondmachines1@infosec.exchange
       0 likes, 0 repeats
       
       Shamelessly stolen from a @protonprivacy commercial
       
 (DIR) Post #B5WMycxpgObfftSJMm by beyondmachines1@infosec.exchange
       1 likes, 0 repeats
       
       Habemus papa pomorum
       
 (DIR) Post #B5aarUpzfrXcR07fCC by beyondmachines1@infosec.exchange
       0 likes, 1 repeats
       
       Not hallucinating, not hitting a token limit. Only uncontrolled expense is coffee.Are "#AI layoffs" coming?
       
 (DIR) Post #B5klbFtIWIWeWNj2jA by beyondmachines1@infosec.exchange
       0 likes, 0 repeats
       
       Notepad++ Patches Critical Format String Injection FlawNotepad++ version 8.9.4 patches a critical format string injection vulnerability (CVE-2026-3008) that allow attackers to crash the application or leak sensitive memory data via malicious language packs.**If you use Notepad++, update to version 8.9.4 immediately through the official website or built-in updater, especially if you use a non-English language pack. Only download language packs from the official Notepad++ source, never from forums or third-party sites.**#cybersecurity #infosec #advisory #vulnerabilityhttps://beyondmachines.net/event_details/notepad-patches-critical-format-string-injection-flaw-w-m-g-l-s/gD2P6Ple2L
       
 (DIR) Post #B5qYSCkcgwizilmWHo by beyondmachines1@infosec.exchange
       3 likes, 2 repeats
       
       #privacy #compliance
       
 (DIR) Post #B5tVauhlRIAHyCmkPw by beyondmachines1@infosec.exchange
       0 likes, 1 repeats
       
       A simple message for the weekend
       
 (DIR) Post #B5zH37I7u5HWkbXjsm by beyondmachines1@infosec.exchange
       0 likes, 1 repeats
       
       Prompt Injection Attack Drains $155,000 from Grok-Linked Bankr Crypto WalletA prompt injection attack against xAI's Grok chatbot exploited the Bankr platform's social-feed command parser to steal $155,000 in cryptocurrency. The attacker bypassed security restrictions by airdropping an NFT to Grok's wallet and using Morse code to trick the AI into broadcasting a transfer command.****#cybersecurity #infosec #incident #thefthttps://beyondmachines.net/event_details/prompt-injection-attack-drains-155000-from-grok-linked-bankr-crypto-wallet-x-q-p-c-p/gD2P6Ple2L
       
 (DIR) Post #B5zTndCmmP5AV5zX84 by beyondmachines1@infosec.exchange
       1 likes, 0 repeats
       
       And they thought V'ger was dangerous.
       
 (DIR) Post #B69quSqzuBikwwcutU by beyondmachines1@infosec.exchange
       0 likes, 3 repeats
       
       Pass it on!
       
 (DIR) Post #B6BIEZC2w8FYK7F4IS by beyondmachines1@infosec.exchange
       1 likes, 0 repeats
       
       How much do you trust a financial platform that says they are vibecoding to production, that just fired 14% of their workforce and are betting their growth on unregulated gambling? Full tweet here: https://x.com/brian_armstrong/status/2051616759145185723
       
 (DIR) Post #B6OOyIwwmrka2tqqRM by beyondmachines1@infosec.exchange
       1 likes, 0 repeats
       
       I have a proposal for a sustainable datacenter 👇
       
 (DIR) Post #B6S7wTE2gqMGkQE7Yu by beyondmachines1@infosec.exchange
       0 likes, 1 repeats
       
       DirtyDecrypt: New Linux Kernel Vulnerability Grants Root Access via RxGK SubsystemA new Linux kernel vulnerability known as DirtyDecrypt (CVE-2026-31635) allows local attackers to gain root privileges by exploiting a missing copy-on-write guard in the RxGK subsystem. The flaw primarily affects bleeding-edge distributions like Fedora and Arch Linux, and a public exploit is now available.**If you're running Linux systems with kernels compiled with `CONFIG_RXGK` enabled (mainly Fedora, Arch, or openSUSE Tumbleweed), update your kernel ASAP, since a working exploit is publicly available. If you can't patch, apply the temporary `modprobe` workaround to disable the vulnerable RxRPC and ESP modules, but test it first as it will break IPsec VPNs and AFS file systems.**#cybersecurity #infosec #advisory #vulnerabilityhttps://beyondmachines.net/event_details/dirtydecrypt-new-linux-kernel-vulnerability-grants-root-access-via-rxgk-subsystem-e-8-v-c-6/gD2P6Ple2L
       
 (DIR) Post #B6SCsE8VLiqWYsQsK0 by beyondmachines1@infosec.exchange
       0 likes, 1 repeats
       
       Critical NGINX Heap Overflow Vulnerability Actively ExploitedF5's NGINX Open Source and NGINX Plus are facing active exploitation of a critical heap buffer overflow (CVE-2026-42945) that allows unauthenticated attackers to cause denial-of-service or remote code execution.**If you're running NGINX Open Source or NGINX Plus, make sure that  ASLR is enabled on your system. Then upgrade to a patched version (NGINX Open Source 1.30.1/1.31.0, or NGINX Plus R36 P4/R32 P6) before attackers find your server. If you can't upgrade right away, change any unnamed captures in your rewrite rules (like $1) to named captures (like (?<id>[0-9]+)) to block the attack path.**#cybersecurity #infosec #attack #activeexploithttps://beyondmachines.net/event_details/critical-nginx-heap-overflow-vulnerability-actively-exploited-q-8-4-h-o/gD2P6Ple2L
       
 (DIR) Post #B6cVQXIGN1QMZw6bmy by beyondmachines1@infosec.exchange
       0 likes, 1 repeats
       
       AI will replace employees, it's cheaper. Oh, wait...
       
 (DIR) Post #B6kW2Vrq9c6zmsHkLQ by beyondmachines1@infosec.exchange
       1 likes, 0 repeats
       
       Critical 7-Zip Vulnerability Allows Remote Code Execution via NTFS Handler7-Zip version 26.00 and earlier contain a critical heap buffer overflow (CVE-2026-48095) in the NTFS handler that allows attackers to execute arbitrary code via a crafted archive. The flaw is extension-agnostic and can be triggered simply by opening a malicious file.**If you use 7-Zip, update to version 26.01 or later immediately. Versions 26.00 and earlier let attackers take over your system just by opening a malicious archive. Until you've updated, do not open any archive or disk image files from untrusted or unexpected sources, regardless of the file extension.**#cybersecurity #infosec #advisory #vulnerabilityhttps://beyondmachines.net/event_details/critical-7-zip-vulnerability-allows-remote-code-execution-via-ntfs-handler-2-b-s-s-0/gD2P6Ple2L